Observations on Operating System Security Vulnerabilities
Stefan Lindskog · 2000
Thesis for the degree of Licentiate of Engineering This thesis presents research on computer security vulnerabilities in general-purpose oper-ating systems. The objective is to investigate intrusions in such systems in order to find and model the underlying generic weaknesses, i.e., weaknesses that would be applicable to many different systems. An attempt is made to create a conceptual basis for the generic modeling of vulnerabilities, addressing security concepts, definitions, and terminology. The investigation of intrusions is based on empirical data collected from three different systems, UNIX, Novell NetWare, and Windows NT. The UNIX and Novell NetWare data were generated from a number of practical intrusion experiments with Master’s students, while the Windows NT data resulted from a security analysis that we performed ourselves. This analysis showed that Windows NT, initially thought to be quite secure, still displayed a significant number of vulnerabilities. A comparison with earlier UNIX analyses indi-cates that the security differences between the systems are related more to factors such as time on market and security-by-obscurity than to inherent security performance. A differ-